Behind the promise of an instant summary or an automated analysis lies a question that has become central for Swiss businesses: what information are we really prepared to entrust to artificial intelligence?
Uploading a document to an AI assistant has become an almost routine gesture. A financial file needs summarising, a contract comparing, meeting minutes restructuring or a presentation preparing. A few seconds are enough to obtain a result that would previously have taken dozens of minutes.
The value is immediate and visible. The risk is far less so.
When an employee drops a business document into an AI service, they are not simply using a productivity tool. They may be passing information to a third-party provider, in an environment whose hosting, retention and reuse conditions are not necessarily known to their employer.
The issue therefore lies not in the feature being used, but in what is sent, in what context and with what safeguards.
As this gesture becomes widespread, businesses face a particularly tangible form of Shadow AI: the use of an AI solution without sufficient visibility, approval or oversight from those responsible for IT, legal affairs or data protection.
01The Risk Rarely Starts With Bad Intent
Shadow AI scenarios generally look nothing like traditional cybersecurity incidents.
There is no spectacular intrusion, no obvious malware and no ransom demand. The starting point is often a perfectly legitimate business need: working faster, cutting down a repetitive task or delivering a result under a tight deadline.
An employee opens an AI assistant available on the internet. They select an internal file, such as a quarterly results spreadsheet, and ask the tool to identify trends. The service produces a summary in a matter of seconds.
From the user’s point of view, the experience is efficient. From the company’s point of view, however, several unknowns may remain:
- has the tool been approved?
- is the account personal or professional?
- what specific data does the document contain?
- where is the processing carried out?
- how long is the information retained?
- can the data entered be reused to improve the service?
- which people or subcontractors can access it?
- can the company trace the operation in the event of an incident?
These questions do not mean that all AI services carry the same level of risk. Above all, they show that an assessment cannot rely solely on a brand’s reputation or the simplicity of its interface.
02A “Simple File” Can Contain Far More Than Meets the Eye
Perceptions of risk are often shaped by the format of the document.
A spreadsheet may seem harmless because it contains no password and no explicit “confidential” label. Yet it can reveal unpublished financial results, margins, customer contact details, salary information or sales forecasts.
A text document may contain a strategy, a legal opinion, the terms of a negotiation or the details of a project that has not yet been made public.
Even an apparently anonymised file can pose a risk. The Federal Data Protection and Information Commissioner (FDPIC) notes that artificial intelligence can make it easier to combine several datasets and to link pseudonymised, or even anonymised, information back to an identifiable individual.
Source: FDPIC — Using artificial intelligence in everyday life
The sensitivity of a document therefore does not depend solely on its title or format. It depends on its content, its context and the possibility of cross-referencing the information it contains with other sources.
03In Switzerland, AI Does Not Operate in a Legal Vacuum
The debate on artificial intelligence sometimes gives the impression that businesses are operating in an environment without rules, pending the adoption of legislation specifically dedicated to AI.
That reading is incomplete.
The FDPIC points out that the Federal Act on Data Protection (FADP) applies directly whenever an AI system processes personal data. The Act is worded in a technology-neutral way and therefore also covers processing carried out using artificial intelligence models.
Source: FDPIC — AI and data protection
Manufacturers, providers and users of AI systems must in particular ensure transparency regarding the purpose of the processing, how the system works and the data sources used. The FDPIC also states that users of a language model must be able to know whether the information they enter is reused to improve the program or for other purposes.
Source: FDPIC — AI and data protection
Where processing presents a high risk for the individuals concerned, the FADP requires a data protection impact assessment.
Source: FDPIC — AI and data protection
The FDPIC reiterated this framework at a conference held in January 2026 with the University of Lausanne, the University of Geneva’s Centre universitaire d’informatique and ThinkServices. The federal authority notably stressed the importance of transparency and of informing users about any use of the data contained in their prompts.
Source: FDPIC — Data Protection Day 2026
For a Swiss business, the question is therefore not only whether an AI service performs well. It is also whether its use makes it possible to comply with existing data protection obligations.
04A Swiss Strategy Built on Trust and a Sector-Based Approach
To date, Switzerland has no general law dedicated to artificial intelligence. The Federal Council has nevertheless set out a regulatory direction built around three objectives: strengthening Switzerland as a centre of innovation, safeguarding fundamental rights and strengthening public trust in AI.
Source: OFCOM — Artificial intelligence
The chosen approach provides for incorporating the Council of Europe Convention on Artificial Intelligence into Swiss law, with adjustments that are as sector-specific as possible. Cross-sector regulation is to focus on areas central to fundamental rights, including data protection.
Source: OFCOM — Artificial intelligence
This approach leaves businesses considerable room to innovate. It does, however, require them to translate the broad principles of transparency, security and accountability into operational rules themselves.
In practice, this means an organisation cannot wait for a future AI law before it starts inventorying its tools, classifying its information or informing its employees.
05The Real Issue Is Not the Tool, but Control Over the Data
Discussions about generative AI frequently focus on the choice of platform. Which model performs best? Which assistant produces the best summaries? Which solution integrates most smoothly into the working environment?
These questions matter, but they come too late if the company has not first defined what can be shared.
Effective governance starts with the data:
- which information is public?
- which information is reserved for internal use?
- which data is confidential?
- which personal or sensitive data requires specific measures?
- which content must never leave a controlled environment?
Once this classification is in place, the company can determine which tools are compatible with each category of information and which controls must be applied.
In this model, an AI assistant is no longer regarded as a mere chatbot. It becomes a component of the information system, with its own providers, access rights, processing activities and contractual obligations.
06A Blanket Ban Can Create Even More Shadow
Faced with uncertainty, some organisations choose to block access to AI services. The decision appears prudent, but it does not always address the need that drives employees to use these solutions.
When a tool delivers genuine time savings, banning it can push usage towards personal devices, private accounts or less visible services. The risk is not eliminated. It simply becomes harder to identify.
A credible policy must therefore go beyond a simple list of prohibitions. It should specify:
- approved tools;
- authorised uses;
- data that may be processed;
- information that must be excluded;
- the procedure for testing a new service;
- the point of contact in case of doubt or error.
Providing an approved alternative is also essential. It is difficult to ask employees to give up a tangible benefit without offering them a tool that meets the same need within a controlled framework.
07Businesses Must Also Prepare for the Error Scenario
No policy will completely eliminate incidents.
An employee may upload the wrong file, use the wrong account or discover afterwards that a document contained information that should not have been shared.
In this situation, the company’s response is decisive.
If the person concerned fears automatic sanctions, their first instinct will probably be to report nothing. The organisation will then lose valuable time and be unable to assess its exposure properly.
An effective security culture should, on the contrary, encourage immediate reporting. The employee should be able to state quickly:
- which tool was used;
- when;
- with which account;
- which file or content was shared;
- which people or data are affected.
This internal transparency allows the IT department, the security officer or the data protection advisor to assess the situation and take appropriate action.
Awareness training should therefore not only teach what not to do. It should also clearly explain how to respond once the mistake has already happened.
08“Stop and Think”: Turning an Instruction Into a Professional Reflex
The difficulty with cybersecurity messages often lies in their abstraction. Employees understand them in theory, but do not necessarily apply them at the precise moment a decision has to be made.
A simple rule can help turn caution into an operational reflex: before uploading a document, pause for a few seconds and consider four dimensions.
Sensitivity
Does the file contain personal, financial, contractual, strategic or confidential data?
Technology
Has the AI platform been approved by the company or its IT provider?
Organisation
Is it being used with an account and within an environment managed by the employer?
Permissions
Does the application request access to files, email, the browser or other connected services?
If any of these dimensions remains uncertain, the right reflex is to pause the operation and request approval.
This pause is not meant to slow down innovation. It is intended to prevent a few minutes saved from causing a lasting loss of control over information.
09From Shadow AI to Governed Artificial Intelligence
AI adoption cannot be managed as a one-off IT project. Models, providers, features and contractual terms evolve rapidly. Governance will therefore need to be continuous.
For Swiss SMEs, a realistic approach can be built around six priorities:
- 1. Inventory actual usage, including tools already adopted by business teams.
- 2. Classify data according to its level of sensitivity.
- 3. Define authorised use cases, rather than a generic ban.
- 4. Approve a limited number of platforms, with terms suited to professional needs.
- 5. Train employees using concrete situations, such as uploading a contract or a financial file.
- 6. Set up a reporting procedure, so that errors can be handled quickly.
These measures are governance choices put forward for businesses. Their implementation must be adapted to the sector, the size of the organisation, the nature of the data processed and the applicable contractual requirements. An IT audit helps establish the starting point.
10Digital Maturity Is Also Measured by What You Choose Not to Send
Generative AI will continue to be built into office software, browsers, collaboration platforms and business applications. Over time, the line between traditional software and AI services will probably become less and less visible.
Dropping a file into a conversational interface may seem trivial. Yet it brings together several of today’s major digital issues: information sovereignty, provider accountability, transparency of processing, compliance and security culture.
The right question is therefore not whether to use artificial intelligence.
It is under what conditions the company can entrust part of its information to it without losing control over its responsibilities.
In this context, taking a few seconds before sharing a document is not a sign of distrust towards innovation. It is the expression of a professional skill that is set to become as natural as checking the recipient before sending an email.
11Practical Checklist: Five Questions Before Uploading a Document
- 1. Is the tool approved for professional use?
- 2. Does the file contain personal or confidential information?
- 3. Is the account being used managed by the company?
- 4. Are the data retention and reuse conditions known?
- 5. Could the operation be explained to a client, an auditor or senior management?
When in doubt, the safest decision is to stop the upload and consult the IT manager or your IT provider.
12Verifiable Swiss Sources
- FDPIC (PFPDT): AI and data protection
- FDPIC (PFPDT): using artificial intelligence in everyday life
- FDPIC (PFPDT): uses of generative AI and data protection issues
- OFCOM: overview and Swiss regulatory approach to artificial intelligence
- Federal Office of Justice: artificial intelligence and the evolving Swiss framework
- Fedlex: Federal Act on Data Protection
- NCSC (OFCS): the influence of AI on social engineering cyberattacks
Are your employees already uploading documents to AI tools?
AWSMTECH helps you map existing usage, classify your data and define an AI usage framework tailored to your organisation.
Talk to an expert



